CVE-2018-5332: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Linux Linux Kernel: before 3.2.99 (fixed in 3.2.99); from 3.3, before 3.16.54 (fixed in 3.16.54); from 3.17, before 3.18.92 (fixed in 3.18.92); from 3.19, before 4.1.50 (fixed in 4.1.50); from 4.2, before 4.4.112 (fixed in 4.4.112); from 4.5, before 4.9.77 (fixed in 4.9.77); …

Published 2018-01-11. Last modified 2026-06-17.